Impact
An integer overflow or wraparound bug in Microsoft Office Word enables an unauthorized attacker to read sensitive data from the process and send it over a network. The flaw can be triggered by crafted documents or inputs, allowing disclosure of confidential information in the memory of the Office process. This weakness is identified as a buffer under‑read (CWE‑125) and an integer overflow (CWE‑190). The impact is the exposure of data that the application or the underlying operating system protects, compromising confidentiality of the user’s documents and potentially internal network data.
Affected Systems
The issue affects multiple Microsoft Office families, including Microsoft 365 Apps for Enterprise, Office 2016, Office 2019, Office 2021, Office 2024, and their Mac variants such as Office 365 for Mac, Office LTSC 2021 and 2024 for Mac. The vulnerability is present in both x86 and x64 builds and applies to the 2016 Word application as well as newer Word versions bundled with these Office suites.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. No EPSS score is available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not widely exploited at present. The likely attack vector is a network‑based attack where an attacker supplies a malicious document or exploits a remote session. Given the moderate severity and lack of publicly known exploits, organizations should treat this as a legitimate risk but the chance of successful attack appears limited so far.
OpenCVE Enrichment